A patched ChatGPT for Mac flaw let code already running on a Mac—without elevated privileges—use a trusted script interpreter to bypass internal checks and potentially access saved chats and connected app data. The issue was a trust boundary failure inside the app, not evidence of a remote attack or unrestricted acc...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trusted. Article summary: Objective-See researchers found a local trust-boundary flaw in ChatGPT for macOS: the app could accept commands from an attacker-controlled script as though they came from a trusted component. An exploit could potentiall. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts wi
Objective-See researchers found that ChatGPT for macOS could mistake commands carried by an untrusted script for requests from a trusted app component. An attacker first needed to run code on the victim’s Mac, but did not need elevated privileges; exploiting the flaw could let that code take over the ChatGPT app and access data available to it. 2
4
7
ChatGPT’s macOS app used process and code-signature checks to distinguish trusted components from untrusted code. The flaw was that an attacker could use a trusted script interpreter to pass an untrusted script into the app. In effect, the checks trusted the interpreter without adequately establishing that the script and the commands it delivered were trustworthy. 4
5
This was a local attack: malicious code had to be running on the same Mac first. The reports describe the needed code as unprivileged, so the attacker did not have to begin with administrator or root access. 7
8
Once the attacker’s commands were accepted as coming from a trusted ChatGPT component, they could potentially read saved conversations and issue commands through the app. The reported impact also included data or services available through ChatGPT integrations, such as browser sessions. 2
4
7
That does not mean the flaw gave an attacker unrestricted control of the entire Mac. The described access was through the compromised app and the data and integrations available to it. 2
7
OpenAI’s macOS changelog listed a fix for CVE-2026-100754 on September 25, 2026, in ChatGPT version 26.924.20706. Reports about the issue appeared publicly on October 2. Users of the Mac app should install the fixed version or a later release. 2
4
7
The vulnerability highlights that an AI app can be a valuable target not only because of what it generates, but also because of what it can access and do. Chat histories and connected services can make a compromised assistant a route to sensitive information. 2
The broader security lesson is about trust boundaries: verifying that a process is signed or trusted is not enough if that process can carry untrusted instructions into an application. Objective-See has described its continuing work as research into AI-agent security, underscoring the need to examine how assistants validate the origin of commands as their capabilities and integrations expand. 14
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A patched ChatGPT for Mac flaw let code already running on a Mac—without elevated privileges—use a trusted script interpreter to bypass internal checks and potentially access saved chats and connected app data.
A patched ChatGPT for Mac flaw let code already running on a Mac—without elevated privileges—use a trusted script interpreter to bypass internal checks and potentially access saved chats and connected app data. The issue was a trust boundary failure inside the app, not evidence of a remote attack or unrestricted access to the whole Mac.